
AWS Fargate
Protect container services that run on AWS Fargate.
Overview
AWS Fargate is serverless compute for Amazon ECS and Amazon EKS containers. AWS manages the underlying compute capacity. A Pomerium deployment must still provide configuration, secrets, network reachability, stable ingress, health checks, and required state.
Teams can use managed container compute while keeping private application access behind one policy point. The access design must still account for Pomerium state and network placement.
AWS Fargate supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A container runtime that can run the official Pomerium image and provide protected configuration, secrets, storage, and a private path to each upstream service.
- A stable user-facing listener with DNS and TLS for the selected routes.
How it works
Run the official Pomerium container through the environment container runtime. Mount protected configuration and secrets, publish the selected user-facing ports, and provide a network path to each upstream service.
Use the official Pomerium container in a reviewed ECS Fargate or EKS Fargate architecture only when the platform features meet the deployment requirements. Keep Pomerium near the private upstream services and provide the required load balancer, DNS, TLS, and persistent state.
Check container health, protected configuration and secrets, the private container network, and upstream reachability. Test an allowed request and a denied request. Confirm that direct service exposure cannot bypass Pomerium.
Example
An ECS service runs a private web application and a Pomerium Fargate task in connected subnets. A load balancer sends the public route to Pomerium. Pomerium sends only approved requests to the application.
Considerations
- There is no named first-party Pomerium Fargate deployment guide.
